Privacy policy
Keep personal information out of the intelligence path.
MIQ is designed to examine dealership operations while keeping customer personal information out before storage. The public website also avoids behavioural tracking, advertising pixels, and session recording.
Effective September 8, 2026 · Campaign notice updated September 8, 2026
No behavioural tracking
No analytics, advertising pixels, heatmaps, session recording, or tracking cookies.
Mandatory intake screening
Where the dealer-side cleaning tool is used, it removes unnecessary personal information before upload. Every authorized operational intake is then independently screened, and detectable personal information is rejected before storage.
Canada-first architecture
Client operational data is designed for AWS ca-central-1 residency and tenant isolation.
1. Scope
This Privacy Policy explains how Mechanus IQ Ltd. collects, uses, discloses, protects, and retains personal information through the public website at mechanusiq.com, contact forms, voluntary RIA campaign support, inbound business communications, and related security systems.
Paid services, pilots, diagnostics, and data processing for a client organization are also governed by the signed client agreement. If a signed client agreement conflicts with this Privacy Policy for client operational data, the signed agreement controls for that client engagement.
Mechanus IQ is built for Canadian dealership operations. Privacy obligations may include PIPEDA and, where applicable, provincial private-sector privacy laws such as British Columbia PIPA, Alberta PIPA, and Quebec private-sector privacy legislation.
2. What we do not collect
We do not run Google Analytics, Google Tag Manager, Meta Pixel, Hotjar, Clarity, Segment, Mixpanel, Amplitude, PostHog, Plausible, Fathom, session replay, heatmapping, behavioural advertising, fingerprinting, or third-party marketing telemetry on the Site.
We do not set tracking cookies. We do not sell personal information. We do not use Site visitors for advertising profiles. We do not train AI models on Site visitor information. Client data is not used for model training unless a written controlled-learning authority is executed under the client agreement.
Mechanus IQ makes a dealer-side cleaning tool available. Where that tool is used, it runs on dealer equipment to remove unnecessary personal information from DMS exports before upload. Every authorized operational export then passes through intake screening that independently rejects detectable personal information before storage. Export templates are designed to exclude customer names, addresses, phone numbers, email addresses, social-insurance numbers, and equivalent direct identifiers. Employee names and DMS user IDs are not accepted on the standard operational upload path. A separately authorized staff-coded workflow may retain dealer-assigned pseudonymous personnel codes; the dealership keeps the code-to-name mapping.
3. What we collect
If you contact us, we may collect the information needed to respond: your name, business email, phone number if provided, organization, role, province or region, message content, and any information you choose to include in the communication.
If you request a pilot, diagnostic, briefing, or commercial conversation, we may collect business-contact information, dealership or group information, scheduling information, stated operational priorities, and the history of our communications with you.
Hosting and security providers may process request metadata such as IP address, user agent, requested URL, timestamp, referrer, device and browser indicators, protocol details, bot-score indicators, and security-event metadata under their own service settings for site operation, security, abuse prevention, incident response, and legal preservation where appropriate, not behavioural advertising. The Mechanus IQ /trap/* control may use request-local information to block a trap request but does not persist that request metadata; its one-day aggregate is described below.
When a dealer becomes a client, Mechanus IQ may process operational dealership data described in the signed client agreement, such as deal logs, funding reports, F and I summaries, service repair-order logs, inventory reports, cancellation records, warranty records, and canonicalized operational versions of those records. The client agreement governs that processing.
4. Why we use information
Mechanus IQ uses personal information for these limited purposes:
- to respond to inquiries and maintain ordinary business-contact records;
- to assess pilot, diagnostic, or commercial fit;
- to schedule calls, prepare conversations, and administer requested communications;
- with express consent, to verify and coordinate RIA campaign support and provide the supporter list to the MLA handling the campaign, as described in section 14;
- to operate, secure, troubleshoot, and improve the Site without behavioural tracking;
- to detect, investigate, prevent, and respond to scraping, bot activity, abuse, security events, or unauthorized access;
- to administer client agreements, security requirements, and data-processing obligations; and
- to comply with legal, regulatory, accounting, tax, insurance, dispute, evidence-preservation, and governance obligations.
5. Disclosure
We do not sell personal information. We do not disclose personal information for third-party advertising. We do not share client operational data with other clients.
We may disclose limited information to service providers that help us operate the Site, secure the Site, process contact requests, host infrastructure, provide email or scheduling services, maintain records, or support legal and accounting administration. Service providers are permitted to use the information only for the service they provide to Mechanus IQ.
We may disclose information where required or permitted by law, including to courts, regulators, law enforcement, professional advisers, insurers, auditors, or counterparties where necessary for legal claims, security incidents, evidence preservation, contract enforcement, corporate transactions, or compliance obligations.
6. Residency and cross-border handling
Client source uploads, storage, logs, evidence, backups, and non-LLM processing are designed for AWS ca-central-1 residency, with tenant isolation and no cross-client reuse unless the client expressly agrees in writing.
The public website is served through Cloudflare and other ordinary internet infrastructure. Website request metadata and security metadata may be processed by those providers in the jurisdictions where they operate, subject to contractual, technical, and organizational safeguards. This edge-security metadata is separate from client operational data.
Any enabled model-assisted inference path must be disclosed according to the client agreement and applicable workflow. Analytical summarization of findings may use a large language model through Amazon Bedrock, and that inference can route through cross-region inference to United States regions. Content sent on that path must have passed intake stripping and PII redaction.
Third-party development and support tooling is not a production subprocessor for client operational data, raw dealer source uploads, customer PII, or dealer-identifying confidential data. Any use of that tooling is restricted to code, public or legal text, non-confidential architecture, synthetic examples, or sanitized excerpts unless a written client-approved and counsel-reviewed process expands it.
Client data is not used to train, fine-tune, or improve AI models by default. Any controlled-learning path requires written authority, signals proven eligible under the governed intake and privacy controls, and documented contractual controls under the client agreement.
7. Retention
Business-contact records are retained for as long as needed to manage the relationship, respond to the inquiry, maintain ordinary business records, and satisfy legal or governance requirements. Non-client inquiries are normally removed or archived after they are no longer operationally required.
Website security retention depends on the record class. The periods below describe Mechanus IQ's current application-level bot-trap controls.
| Record class | Current handling | Application-level period |
|---|---|---|
| Ordinary website requests | Under the current /trap/* route, ordinary page requests are not written to the bot-trap violation store. | No Mechanus IQ bot-trap violation store retention period. |
| Honeypot events under /trap/* | When a request reaches a /trap/* path and the security store write succeeds, a best-effort, non-identifying aggregate count is recorded for security review. No IP address, user-agent, requested URL, headers, TLS fingerprint, location, ASN, or visitor-derived identifier is written. | The hourly aggregate expires 1 day after the bucket was last updated. |
Provider-side edge records are separate from the Mechanus IQ bot-trap violation store. Cloudflare and other infrastructure providers may process and retain their own operational or security records under the applicable service settings and legal obligations; the periods above do not state or control those provider periods.
If a legal hold or preservation duty applies, a separately authorized preservation step must occur before the applicable application-level expiry. The bot-trap expiry control does not extend itself. Records are destroyed or de-identified when their identified security purpose is no longer being served and retention is no longer necessary for legal or business purposes, as required by applicable law.
Client operational data follows the signed client agreement and the applicable retention schedule. Destruction, export, hold, and preservation obligations are handled under that agreement.
8. Safeguards
Mechanus IQ uses administrative, technical, and physical safeguards appropriate to the sensitivity of the information. Safeguards may include access controls, least-privilege access, encrypted transport, tenant isolation, audit logging, security headers, Cloudflare edge controls, bot-trap controls, and documented incident-response procedures.
No internet system is perfectly secure. Mechanus IQ limits collection, avoids tracking, separates public website metadata from client operational data, provides a dealer-side cleaning tool for use before upload, and independently rejects detectable personal information at intake before storage.
Technical details are summarized at /platform/infrastructure/security.
9. Your rights and choices
Subject to applicable law and verification of identity, you may request access to personal information we hold about you, correction of inaccurate information, withdrawal of consent where consent is the basis for processing, deletion where legally available, or information about how your information has been used or disclosed.
Requests should be sent to privacy@mechanusiq.com. We respond within the legally required period, which is normally 30 days unless an extension or different statutory timeline applies.
If you have a concern that we cannot resolve, you may contact the Office of the Privacy Commissioner of Canada or, where applicable, the provincial privacy regulator with jurisdiction over the matter.
10. Marketing and communications
We may use business-contact information to respond to a request, continue an active business conversation, or send information directly related to the matter you raised. We do not add website visitors to behavioural advertising audiences.
If we send a commercial electronic message that requires unsubscribe functionality under applicable anti-spam law, we will include an unsubscribe method. You may also ask us to stop non-essential communications by contacting privacy@mechanusiq.com.
11. Children
The Site is a business-to-business website for dealership operators, lenders, professional advisers, and business reviewers. It is not directed to children, and we do not knowingly collect personal information from children through the Site.
12. Changes
We may update this Privacy Policy by posting a revised version with a new effective date. Changes apply prospectively from the effective date shown unless a different effective date is required by law.
13. Contact
Privacy inquiries and access requests: privacy@mechanusiq.com. Jurisdiction: British Columbia, Canada.
Legal and website-access questions may also be sent through the contact form at /start#contact.
14. RIA campaign support
The RIA transparency campaign has a voluntary online supporter list, separate from its printable formal petition. Mechanus IQ collects a supporter's name, municipality or community, email, B.C. residency attestation, supported request, consent wording and version, and request and confirmation times. Confirmation establishes control of an email address; it does not independently verify identity or residency.
With the express consent given on that form, Mechanus IQ will share the confirmed supporter's name, municipality, email, support and consent record with the MLA handling the campaign and their constituency staff for the RIA submission. We do not publish individual supporters, add campaign contacts to a marketing list, or use them for AI processing. The receiving office handles its copy under its own obligations and procedures; we cannot promise that its records will remain confidential in every circumstance.
Cloudflare handles the form, human verification and network traffic; Resend delivers the confirmation email. These providers may process information outside Canada. Campaign records are held in a separate table in Mechanus IQ's local database and are not dealer operational records. For abuse prevention, short-lived rate-limit counters use keyed representations of network and email identifiers rather than displaying them publicly.
Unconfirmed entries expire after 24 hours. Confirmed entries expire 180 days after confirmation. Expired entries stop counting and are excluded from exports; hourly cleanup removes them from the active database. The withdrawal link removes an active record sooner. Restricted backup copies and email-provider records may remain under their separate retention arrangements. The active supporter count is not a historical total and is never combined with handwritten petition signatures.
Use the withdrawal link in the confirmation email before handoff. After handoff, withdrawal from Mechanus IQ does not recall the office's copy; you may also need to contact that office. For a correction, access request, lost link or help following up with the receiving office, contact privacy@mechanusiq.com. Completed formal paper petitions have their own public-record consequences, shown on each printable sheet.
Security posture
Technical safeguards, tenancy isolation, encryption posture, and incident-response controls are summarized at security posture.